ZeroHour
Kaspersky Securelistpublished ()ingested GReAT

Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection

highThreat actor exploited in the wildimportance 55
AI summary · glm-5.3

Project CAV3RN continues targeting Israel, using Google Apps Script C2 relays and DNS-based channel routing in a .NET NativeAOT framework.

Kaspersky Securelist documents the continuation of Project CAV3RN operations against Israel. The modular .NET NativeAOT framework uses Google Apps Script as a C2 relay and DNS-based C2 channel selection, blending command traffic with legitimate Google services to evade detection.

  • Ongoing campaign targeting Israeli organizations
  • Google Apps Script abused as C2 relay
  • DNS-based C2 channel selection mechanism
  • .NET NativeAOT modular framework evades detection
Full article

Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate Google services to evade detection.

This source does not provide full text. Read it at securelist.com.